216.73.216.6

Beyond the wail: deconstructing the BANSHEE infostealer

· Published 16/08/2024 14:10 · Modified 16/08/2024 14:50

Export JSON

Essential information

Published
16/08/2024 14:10
Modified
16/08/2024 14:50
Tags
2024-08-16 banshee stealer c++ infostealer macos sysctl api
Related entities
2 observables, 1 intrusion sets (apt), 12 techniques (mitre), 1 malware

Description

This analysis details the BANSHEE malware, a -based that targets system information, browser data, and cryptocurrency wallets. Developed by Russian threat actors, it operates across x86_64 and ARM64 architectures. The malware is designed to evade detection through anti-debugging measures and checks for virtualization and language settings. It collects user passwords, system information, browser data from various browsers, and data from around 100 browser extensions. Additionally, it targets cryptocurrency wallets like Exodus, Electrum, and Ledger. The collected data is compressed, encrypted, and exfiltrated to a remote server.

External references